Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
Hugging Face, a platform that hosts AI models and datasets, said its internal datasets and service credentials were compromised in a hack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident. In a blog post, the company said a dataset uploaded to its platform abused a security vulnerability to run malicious code on its servers, allowing the attackers to escalate their permissions and gain broader access to Hugging Face’s internal systems.
- ▪Hugging Face, a platform that hosts AI models and datasets, said its internal datasets and service credentials were compromised in a hack last week.
- ▪The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident.
- ▪In a blog post, the company said a dataset uploaded to its platform abused a security vulnerability to run malicious code on its servers, allowing the attackers to escalate their permissions and gain broader access to Hugging Face’s interna
Opening excerpt (first ~120 words) tap to expand
Hugging Face, a platform that hosts AI models and datasets, said its internal datasets and service credentials were compromised in a hack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident. In a blog post, the company said a dataset uploaded to its platform abused a security vulnerability to run malicious code on its servers, allowing the attackers to escalate their permissions and gain broader access to Hugging Face’s internal systems. The company said it has revoked and rotated the stolen credentials that were accessed. It urged users to do the same with any keys stored on the platform, and review any suspicious activity on their accounts.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at TechCrunch.